On Secure Quantum Key Distribution Using Continuous Variables of Single Photons 
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We analyse the distribution of secure keys using quantum cryptography based on the continuous 
variable degree of freedom of entangled photon pairs. We derive the information capacity of a scheme 
based on the spatial entanglement of photons from a realistic source, and show that the standard 
measures of security known for quadrature-based continuous variable quantum cryptography (CV- 
QKD) are inadequate. A specific simple eavesdropping attack is analysed to illuminate how secret 
information may be distilled well beyond the bounds of the usual CV-QKD measures. 
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The distribution of secret information via optical chan- 
nels, e.g. quantum key distribution (QKD), provides 
an important example of the technological capability of 
quantum correlations. The QKD protocol proposed by 
Bennett and Brassard [l[ and its large collection of varia- 
tions 0] , including QKDs using nonorthogonal states Q 
and entangled photons 0] , employ single photons or pho- 
ton pairs to ensure secure information transfer between 
the source (Alice) and receiver (Bob). The quantum 
information associated with the single-photon states in 
these schemes is encoded as dichotomic variables, e.g. in 
the polarization or relative phases of single-photon su- 
perposition states Thus the maximum achievable 
information transfer rate is intrinsically limited to one 
bit per photon. A newer development of QKD utilizes 
continuous variable (CV) multi-photon systems @, 0, @| 
where the amplitude and phase quadratures of coherent 
states 0, [To| or squeezed states [HI [H| serve as the in- 
formation carriers. CV-QKD systems potentially enable 
higher key distribution rate. Recently, single-photon CV- 
QKD employing the position and momentum observables 
has been suggested as a means to increase the informa- 
tion transfer rate by coding more than one bit per pho- 
ton. Compared to quadrature-based CV-QKD, single- 
photon CV-QKD eliminates the local oscillators required 
for homodyne detection and, as we will show, decouples 
the channel loss from the quantum correlations. Experi- 
mental implementations have demonstrated the feasibil- 
ity of these schemes by utilizing the spatial freedom of 
single photons [l3} or entangled photon pairs generated 
by parametric down-conversion (PDC) [lJ,[lB|. Yet, the 
security of such schemes has not been analysed, and as we 
show here, this is not a trivial extension of either BB84 
or the conventional CV-QKD security proofs. 

In this Letter, we evaluate the potential of the spatial 
properties of PDC for QKD by considering a realistic 
PDC source as well as practical detectors and a lossy 
quantum channel. The analysis here also works for CV- 
QKD employing the correlations of time-frequency en- 
tangled photon pairs Spatial correlations are, how- 
ever, easier to manipulate with current technology, al- 
lowing more complete assessments of the channel secu- 



rity. In our analysis we derive the mutual information 
of the communicating parties from measurable postion- 
momentum correlations of PDC states and bound the 
information of a potential eavesdropper (Eve) by ana- 
lyzing detected photocount statistics. Our results lie in 
the region between conventional dichotomic and continu- 
ous variable QKD and highlight the differences between 
these alternative approaches in terms of the experimen- 
tal imperfections corrupting the secrecy of the key ex- 
change. Our security analysis, which is mainly based 
on an intercept-resend eavesdropping strategy, indicates 
that single-photon CV-QKD gives increased secure bit 
rates per photon for intermediate channel losses. 

During the process of PDC, the pump photon with 
wave vector k p spontaneously splits into two lower fre- 
quency (signal and idler) photons with wave vectors fc s 
and ki . The spatial and spectral properties of the photon 
pair are correlated by the material dispersion. In what 
follows it is assumed that the state is spectrally filtered 
such that the frequencies of signal and idler photons are 
restricted to lo s q = LUio = uj p /2. The resulting two-photon 
state is 
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For the practical PDC source, the down-converted modes 
are usually close to the longitudinal axis with the trans- 
verse vectors |fcj- 1 <C k s and |fe^ | <C h (k s /j = |fe s /i|)- 
For a pump beam with a Gaussian profile the biphoton 
amplitude f(k^~; k^~) can be approximated by 



= C exp 
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and where a(k^- + kj~) originates from the pump en- 
velope and transverse phase-matching function, while 
't'Likjr — k^) is the longitudinal phase-matching function. 
C is the constant for normalization, K — k s — ki, wq is 
the beam waist of the pump and L denotes the length of 
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the nonlinear crystal in z direction 17]. Retaining the 



longitutional phasematching function <f> l (kj~ — k^ ) is crit- 
ical to bounding the shared information from above [l^ ] . 

The joint probability distribution of fej~ and fe^ is given 
by p(kj-;kj-) = \f(kjr;k^)\ 2 . The mutual information 
between k^r and fcf can be calculated from 12 fi 



I(k^,kt) + I(r^r t L ) 
2 



I{ki-ki) = H{kt)-H(ki\ki). 



(3) 



where H(k^) and H{k^ \ kg) denote the entropy and 
conditional entropy respectively. Similarly, the Fourier 
transform of Eq. (|2|) determines the mutual information 
I(rjr\r^) between the transverse positions of the two 
photons. We model our practical source of entangled 
photon pairs by considering degenerate Type-I PDC in a 
BBO crystal with a phase-matching angle of 3°, pumped 
at 400nm. Fig. Q] shows the calculated maximum mutual 
information that Alice and Bob can extract if they adopt 
a symmetric coding, i.e. they measure with equal proba- 
bilities the position and momentum of the photons. The 
graph illustrates the information transfer gain for CV 
single-photon systems. This should be compared with 
binary coding, for which a maximal value of one is ob- 
tained. For a fixed pump power, the amount of shared 
information between PDC photons may be increased by 
increasing the pump waist wq and decreasing the crystal 
length L, though the penalty is a reduced efficiency of 
photon-pair generation, resulting in low signal rates. The 
entanglement of the two-photon state in our analysis can 
be characterized by considering the correlations or the 
mutual information for direct measurements of a pair of 
conjugate continuous variables, namely the position and 
momentum of the photons. Alternatively, one may quan- 
tify the entanglement contained in this degree of freedom 
by decomposing the state into its Schmidt modes [2l|, 
and evaluating the corresponding concurrence. We ver- 
ified that this approach yields the same asymptotic be- 
havior, which confirms the consistency of our results with 
more general entanglement measures. QKD further re- 
quires that the measurements of non-corresponding vari- 
ables do not exhibit correlations; our calculations show 
that the mutual information between momentum and po- 
sition (I(kj-;r^-) and I(r^-;k^)) is negligible. 

To analyse the security of a single-photon CV-QKD 
system we choose a specific protocol. Pairs of entangled 
photons are generated in the nonlinear crystal and trans- 
mitted to Alice and Bob separately via a quantum chan- 
nel. The two parties choose randomly to detect either the 
position (r ) or momentum (k^) of each photon they 
receive. Then Alice and Bob announce by an authenti- 
cated public channel the variables which they measured 
for each photon and drop the bits where they used dif- 
ferent variables; the remaining bits constitute the sifted 
raw key. To accomplish a successful quantum key distri- 
bution, the system must allow Alice and Bob to distill a 
secret key from the sifted raw key that is inaccessible to 
the adversary, Eve. With forward reconciliation 22J and 
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FIG. 1: Mutual informations for entangled photon pairs gen- 
erated by Type-I PDC in BBO crystal. This figure shows 
how the crystal length and the pump waist affects the aver- 
aged mutual information in momentum and position. 



privacy amplification [23(, the achievable secret key rate 
in momentum is bounded below by 

AI = I AB -I AE = H(k A \E)-H{k A \k B ), (4) 

where E is the result of Eve's measurement on her ancilla. 
For individual attacks, it has been shown that there exists 
the entropic uncertainty relation [24| 



H(k A | E) + H{r A | r B ) > log 2 ne, 
The conditional entropy is bounded by [25| 



(5) 



1 



H(x A | x B ) < - log 2 [2neA 2 (x A \ x B )] , (6) 

where x stands for k or r, while A 2 denotes the variance. 
By combining Eqs. (|4][6]), we find 



AI > log 2 ire - H (r A \ r B ) - H(k A \ k B 

1 (1 1 

- 2 °S2 [ 4A 2 {rA \r B )A 2 (k A \k B ) 

So a sufficient condtion for AI > is 

A 2 (r A | r B )A 2 {k A \k B )<\ 



(7) 



(8) 



This result also applies for the security analysis in po- 
sition. For high entanglement, this condition coincides 
with the EPR criterion [26] . It is easy to prove from Eq. 
([2]) that the states generated by PDC satisfy this condi- 
tion, as demonstrated recently OjEUE^]- Note, how- 
ever, almost all of these experiments employ one detector 
to scan through the momentum or position values, so in 
principle the outcome of each measurement is binary: ei- 
ther the photon hits the detector or not. Therefore this 
setup is not suitable for single-photon CV-QKD. To re- 
alise the full potential of continuous variables without 
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complex encoding, a sufficiently large array of detectors 
(APDs, pixels of a CCD camera, etc.) is needed to ensure 
that binning and truncating do not significantly dimin- 
ish the information transfer rate [28]. This implies that 
the dark count of the detectors will have a much higher 
impact on the error rate than in standard BB84, though 
the probability that Eve can guess the correct result also 
decreases with the increased number of detectors. 

To see this, assume that the entangled photon pair is 
generated from the pump pulse with probability Ppdc 
and sent to Alice and Bob through two quantum chan- 
nels with throughtputs tj\ and ts- To measure the con- 
tinuous variables r or k 1 - each party maps the distri- 
bution to n identical detectors that are time-gated syn- 
chronously with the pump pulse. We denote the proba- 
bility of recording a dark count within the detection time 
window for each detector as Pdark and its efficiency as rj. 
Alice and Bob keep the results when one and only one 
detector clicks. So there are three cases to be considered: 
(1) both parties have a dark count; (2) one party detects 
a photon and the other has a dark count; (3) both parties 
detect a photon. The probabilities for each case are: 

Pi = [1 - Ppdc + Ppdc{1 - r)t A ){l - rit B )] 

x n 2 P 2 M - P,, A 2n - 2 
X n r dark\ l ^dark) , 

P2 = PpDc[vtA(l - Tfts) + (1 - VtAHB] ^ 

X nP dark {\ - Pdark) 2 "^ 1 , 

P3 = PpDCV 2 tAt B (l - Pdarkf n - (9c) 

respectively. The probability that the photon and a dark 
count arise at the same detector simultaneously is negligi- 
ble. Among all the cases, only P3 will reveal the quantum 
correlations. This probability decreases as the channel 
loss and number of detectors increase due to the increase 
of the background noise level. Some typical values for the 
realistic system with APDs as detectors and nanosecond 
time gating are Ppdc = 0.01, 77 = 0.6 and Pdark = 10~ 6 . 
We fix the length of the BBO crystal to 2mm and as- 
sume a 2mm pump waist (FWHM). The source lies at 
Alice's station, i.e. ^ a 1 and ts — t, where t is the 
transmission of the channel between Alice and Bob. Tak- 
ing into account the dark count contribution according 
to Eq. ([9]), Eq. |J5]) is satisfied for channel throughput 
above t = 36% (68%) (4.4dB (1.7dB) channel loss) as- 
suming a detector array with n = 128 (256) pixels. For 
free space transmission the extinction coefficient varies 
over a large range [2{|. Here we assume it is ldB/km, so 
the corresponding distance is 4.4km and 1.7km respec- 
tively. At these distances the probability of uncorrelated 
events Pi + P2 is less than 1%, which means that the 
noise level is still extremely low. 

Analysis of the variance product seems to suggest that 
this QKD scheme is not suitable for long-distance use. 
But we note that Eq. (J5J) is a tight bound for general 
CV-QKD schemes and it is possible to loosen the bound 



when considering the special characteristics of the ex- 
perimental imperfections in the single-photon CV-QKD 
protocol. Reconsidering Eqs. HUH]), note that the equal- 
ity in Eq. {2} can only be achieved when Eve's attacks 
satisfy certain strict conditions. The most important 
condition is that the distribution of Bob's measurement 
outcomes conditioned on Alice's results should be Gaus- 
sian [25)]. A Gaussian attack is well known to be opti- 
mal for conventional CV-QKD using the quadratures of 
multi-photon states since in these systems experimental 
imperfections — mainly the loss of the channel — will pre- 
serve the Gaussian character of the transmitted state, 
broadening Bob's distribution. By replacing the chan- 
nel with a lossless one and applying a Gaussian attack, 
Eve can hide behind the existing experimental imperfec- 
tions. The normal way for Alice and Bob to detect Eve 
is to monitor the covariance matrix of their results. In 
contrast, for single-photon dichotomic- variable QKD, the 
experimental imperfections (loss, noise, etc) yield uncor- 
related detection events between Alice and Bob, which 
are typically interpreted as background noise. In single- 
photon CV-QKD the experimental imperfections play a 
similar role to those in standard dichotomic single-photon 
QKD. The events registered by each party are either from 
the PDC photons or from the detector noise, and the 
latter has a uniform distribution. Hence Alice and Bob 
expect un-broadened Gaussian joint probability distribu- 
tions from the quantum correlation measurements inter- 
spersed with uncorrelated flat background events, which 
in total represents a non-Gaussian distribution. In or- 
der to stay undetected Eve must mimic this distribution, 
therefore she only has limited options and the optimal at- 
tack for multi-photon CV-QKD is prohibited here. More- 
over, for non-Gaussian distributions, the left side of Eq. 
([7|) can be much bigger than the right side, which means 
even when the EPR condition is violated, it is still pos- 
sible for Alice and Bob to draw the secret key. 

A possible eavesdropping strategy that satisfies the 
above conditions is an intercept-resend attack: Eve inter- 
cepts the photon sent to Bob, measures it in the randomly 
chosen variable (momentum or position), and resends a 
photon in the eigenstate based on her measurement re- 
sult. If, by chance, she has chosen the same measurement 
basis as Alice and Bob, her operation will appear as an 
undisturbed channel between these two parties. Other- 
wise, measuring the conjugate variable Eve introduces 
a flat background noise, which cannot be distinguished 
from the dark noise of the detector array. Therefore by 
adjusting the loss of the channel, Eve can hide her distur- 
bance behind the experimental imperfections. We define 
an intercept-resend ratio A as 

Number of photons intercepted by Eve 
Total number of photons Alice sends to Bob 

By balancing the disturbance introduced by Eve with the 
background noise, which originates from the experimen- 
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Channel Loss / (dB) 

FIG. 2: The minimum secret information per recorded pho- 
ton pair (A/ mm ) is estimated numerically from X m ax- The 
corresponding channel loss I is calculated from Eq. (|10[) . The 
initial entangled photons are generated by a 2mm-long BBO 
crystal and a pump at 400nm with 2mm beam waist. 



tal imperfections, we find an allowed maximum intercept- 
resend ratio for Eve is: 




(10) 



where I is the channel loss and n is the number of detec- 
tors. For a lossless channel (I — 0) or noiseless detectors 
{Pdark = 0), X m ax = 0, i.e. no eavesdropping is possible; 
while for fixed I and Pdark, A maa; increases with n. Eq. 
(JTUJ) clearly shows how the experimental imperfections 
open loopholes for Eve to attack. Moreover, the mini- 
mum secret information that Alice and Bob are able to 



distill (Ar 



jmin 
AB 



Iae x ) can be directly estimated 



transmission loss is shown in Fig. [2] Comparing this re- 
sult with the variance product analysis, it is evident that 
the secure loss level (35dB for n — 128) is significantly 
improved for this eavesdropping strategy. 

An important question in quantum cryptography is the 
relationship between entanglement and security. It has 
been proved that distributed entanglement between Al- 
ice and Bob is a necessary precondition for secret key 
distribution [30| . Also the connection between quantum 
and secret correlations has been established [3lJ. Nev- 
ertheless it is still not clear how to draw a secure key 
from the distributed entanglement. For classical privacy 
amplification (forward or reverse reconciliation), the se- 
curity limit is usually a stronger condition than the en- 
tanglement threshold [13] • In the intercept-resend attack 
for our protocol, the logarithm negativity as a function 
of the intercept fraction A shows that Alice and Bob re- 
main entangled until A — 1, while as Fig. [2] and Eq. 
(fl~0"|) show, the classical privacy amplification requires 
A < 75% (where AI min = 0) to draw the secret key. 
Hence for a practical QKD scheme, the detection of en- 



tanglement may not be enough for secret key distillation. 

To conclude, we have shown the potential to trans- 
fer more than one bit of information per photon using 
the spatial degrees of freedom of the entangled photon 
pairs. Due to the special non-Gaussian distributions of 
Alice and Bob's measurement results, the options for 
eavesdropping are severely limited. A detailed security 
analysis on a plausible attack, intercept-resend, is given. 
Whether Eve gains by means of more powerful attacks 
requires further study. In particular, a more detailed 
analysis of the impact of binning the information is re- 
quired for a practical QKD system with limited number 
of detectors. Refinement of the security analysis will also 
take into account of the turbulence effects for free space 
transmission, which will give Eve more options to attack. 
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